Security Notes
Networking

Wireless, VPNs, Network Access Control & Segmentation

Enterprise network security beyond TCP/IP and DNS: how Wi-Fi is secured and attacked, how IPsec and other VPNs protect traffic between sites and users, how network access control decides which devices may connect, how networks are segmented, and what changes when voice and storage run over IP. For the protocol foundations see TCP/IP and TLS.

11 min read 5 sections 6 model answers

Wireless Security

What is this?

Wi-Fi sends traffic through the air, where anyone nearby can receive it. Wireless security is how a network proves who may join and encrypts traffic so eavesdroppers can't read it.

Why it matters

A wireless network extends your perimeter into the car park. Weak Wi-Fi security gives an attacker a network foothold without ever entering the building, and a fake access point can harvest corporate credentials.

How it works

StandardYearStatus
WEP (Wired Equivalent Privacy)1997Broken. RC4 with short, reused initialisation vectors; key recoverable in minutes.
WPA (Wi-Fi Protected Access)2003Stop-gap using TKIP; deprecated.
WPA22004AES-CCMP; still widely used. Personal mode vulnerable to offline password cracking.
WPA32018SAE handshake, forward secrecy, protected management frames required.

Two modes:

Personal (PSK, pre-shared key)

everyone shares one passphrase. In WPA2-Personal, an attacker who captures the four-way handshake (or a PMKID from one frame) can guess passwords offline at high speed. WPA3-Personal uses SAE (Simultaneous Authentication of Equals), which forces each guess to be an online interaction, defeating offline cracking, and gives forward secrecy.

Enterprise (802.1X)

each user or device authenticates individually through a RADIUS server, typically with EAP-TLS (client certificates, strongest), PEAP or EAP-TTLS (a TLS tunnel wrapping a password). WPA3-Enterprise also offers a 192-bit mode for high-security networks.

Enhanced Open (OWE, Opportunistic Wireless Encryption) encrypts open guest networks without a password, protecting against passive sniffing (not against a rogue access point).

802.1X / EAP-TLS join
Laptop (supplicant) ──EAP──► Access point (authenticator) ──RADIUS──► Auth server (NPS/ISE/FreeRADIUS)
     │◄────────────── TLS handshake inside EAP: server cert checked, client cert presented ─────►│
     │◄────────── success + per-session keys derived ──────────────────────────────────────────│
     └── then the 4-way handshake installs encryption keys for this session only

Wireless attacks

Evil twin / rogue access point

an attacker broadcasts the corporate network name; clients that don't validate the server certificate in PEAP hand over credential hashes. Defence: EAP-TLS, or enforce server certificate validation and the expected server name on every client.

Deauthentication attack

forged management frames kick clients off to capture a handshake or force them onto an evil twin. Defence: protected management frames (mandatory in WPA3).

Offline PSK cracking

capture handshake or PMKID, crack with a GPU. Defence: WPA3-SAE, long random passphrases, or move to Enterprise.

KRACK

key reinstallation attacks against the WPA2 handshake (CVE-2017-13077 and related). Fixed by client and access point patches.

WPS PIN brute force

Wi-Fi Protected Setup's 8-digit PIN is checked in two halves, so it falls in hours. Disable WPS.

Bluetooth

bluejacking (unsolicited messages), bluesnarfing (data theft) and implementation bugs; keep devices non-discoverable and patched.

In practiceThe client setting that decides whether an evil twin works is server-certificate validation. A correct enterprise Wi-Fi profile pins the CA and the server name:

# wpa_supplicant.conf — WPA2/WPA3-Enterprise with EAP-TLS
network={
    ssid="ACME-Corp"
    key_mgmt=WPA-EAP
    eap=TLS
    identity="laptop-4471@acme.com"
    ca_cert="/etc/certs/acme-radius-ca.pem"            ← only trust our RADIUS CA
    domain_match="radius.acme.com"                     ← and only this server name
    client_cert="/etc/certs/laptop-4471.pem"
    private_key="/etc/certs/laptop-4471.key"
    ieee80211w=2                                       ← protected management frames required
}

Remove the two validation lines and the laptop will authenticate to any access point broadcasting "ACME-Corp."

🎯

On the job. Check managed Wi-Fi profiles (MDM / Group Policy) for server-certificate validation, prefer EAP-TLS with device certificates, and make sure guest Wi-Fi lands on an internet-only network.

Security angle

Wireless intrusion detection (WIDS) watches for rogue access points and deauthentication floods. Put guest Wi-Fi on a separate network with internet access only.


IPsec and VPNs

What is this?

A VPN (virtual private network) creates an encrypted tunnel across an untrusted network so that traffic behaves as if on a private network. IPsec (Internet Protocol Security) is the standard suite that does this at the network layer.

Why it matters

IPsec underpins site-to-site connections between offices and clouds, and many remote-access VPNs. VPN appliances are also among the most exploited internet-facing devices, so they matter to both defenders and attackers.

How it works

IPsec has two protection protocols and two modes:

AH (Authentication Header, RFC 4302)

integrity and origin authentication of the whole packet including the outer IP header, no encryption. Breaks through NAT, because NAT changes the header AH protects. Rarely used today.

ESP (Encapsulating Security Payload, RFC 4303)

encryption and integrity of the payload. What almost everyone uses.

Transport mode (host-to-host): original IP header kept, payload protected
  [ IP hdr ][ ESP hdr ][ TCP + data (encrypted) ][ ESP trailer/auth ]

Tunnel mode (gateway-to-gateway, site-to-site VPN): whole original packet wrapped
  [ NEW IP hdr ][ ESP hdr ][ original IP hdr + TCP + data (encrypted) ][ ESP auth ]
Security association (SA)

a one-way agreement on algorithms and keys, identified by an SPI (security parameter index). A two-way tunnel needs two SAs.

IKE (Internet Key Exchange)

, current version IKEv2 (RFC 7296) — authenticates the peers (certificates or pre-shared keys) and negotiates SAs using Diffie-Hellman, on UDP 500. NAT traversal wraps ESP in UDP 4500.

Other VPN types:

TLS VPNs

(often called SSL VPNs) — remote access over HTTPS through a browser or client; easy through firewalls.

WireGuard

a small, modern VPN with fixed modern cryptography and very little configuration.

Split tunnelling

only corporate traffic goes through the VPN; internet traffic goes direct. Better performance, less visibility and control.

In practiceWhat a healthy site-to-site tunnel looks like on a strongSwan gateway:

console
$ swanctl --list-sas
office-to-aws: #12, ESTABLISHED, IKEv2, 1d2f…_i 8a9b…_r
  local  'vpn.office.acme.com' @ 198.51.100.10[4500]
  remote '35.176.0.10' @ 35.176.0.10[4500]                 ← port 4500 = NAT traversal in use
  AES_GCM_16-256/PRF_HMAC_SHA2_384/ECP_384                  ← IKE: modern AEAD + ECDH
  established 3h ago, rekeying in 20h
  office-net: #31, INSTALLED, TUNNEL, ESP:AES_GCM_16-256     ← tunnel mode, ESP
    10.10.0.0/16 === 10.200.0.0/16                         ← only these networks cross the tunnel
📰

Real incident — Fortinet VPN credential leak (2021). A path-traversal flaw in FortiGate SSL-VPN (CVE-2018-13379), patched in 2019, let attackers read a file containing users' VPN credentials. In 2021 a criminal forum published working credentials for around 87,000 devices that had never been patched — or had been patched without resetting passwords. Patching closes the hole; it doesn't revoke what already leaked.

🎯

On the job. For every VPN appliance: patch on an emergency timeline, require MFA, alert on logins from new countries, and after any credential-exposure bug, force password resets as part of the fix.

Security angle

  • VPN concentrators are a top initial-access target; many mass-exploitation campaigns have hit edge VPN appliances. Patch them as emergencies and put them behind MFA.
  • A VPN puts a device on the network; if the device is compromised, so is your network. This is why zero-trust access (per-application, per-request) is replacing broad VPN access. See AWS Verified Access.
  • Pre-shared keys in site-to-site VPNs are often weak and never rotated; prefer certificates.

Network Access Control and Segmentation

What is this?

Network access control (NAC) decides whether a device may connect to the network at all, and which part of it. Segmentation divides the network so that a compromised device can reach as little as possible.

Why it matters

Ransomware spreads laterally across flat networks. Segmentation turns "the whole company is encrypted" into "one segment is."

How it works

NAC

  1. A device plugs in or joins Wi-Fi.
  2. 802.1X authenticates the device or user through RADIUS (devices that can't do 802.1X, like printers, fall back to MAC authentication bypass, which is weak because MAC addresses are easy to spoof).
  3. Posture check — is the device managed, patched, running EDR (endpoint detection and response)?
  4. The device is placed in the right VLAN or given the right access list: corporate, quarantine/remediation, guest or denied.
  5. Continuous monitoring can move it later if posture changes.

Segmentation building blocks

VLANs (virtual LANs)

separate layer 2 broadcast domains on shared switches; need a firewall or router access lists between them to actually enforce policy. Watch for VLAN hopping (switch spoofing, double tagging).

Screened subnet (DMZ)

a zone for internet-facing servers, between two firewalls or firewall interfaces, so a compromised web server doesn't land on the internal network.

Micro-segmentation

policy per workload rather than per subnet, enforced by host firewalls, hypervisors, cloud security groups or a service mesh. East–west traffic is denied by default.

SDN (software-defined networking)

the control plane (decisions) is separated from the data plane (forwarding) and run centrally, so segmentation policy is code. The controller becomes a high-value target.

Firewall generations

packet filter (addresses and ports), stateful (tracks connections), application proxy (terminates and inspects), next-generation (application awareness, user identity, IPS). IDS detects and alerts; IPS sits inline and blocks.

📰

Real incident — NotPetya (2017). Delivered through a hijacked update of Ukrainian accounting software, NotPetya spread across flat corporate networks in minutes using stolen credentials and an SMB exploit, wiping machines at Maersk, Merck, FedEx/TNT and others for an estimated $10 billion in damage. Organisations with segmented networks and restricted admin credentials lost far less.

🎯

On the job. Test segmentation the way an attacker would: from a standard workstation, try to reach domain controllers, backup servers and other workstations on SMB, RDP and WinRM. Every successful connection that isn't needed is a lateral-movement path.

Security angle

Segment by what talks to what, not by org chart. Start by mapping actual flows (flow logs, NetFlow), then deny everything else; the crown jewels (domain controllers, backup servers, hypervisor management) get the tightest zones.


Converged Protocols

What is this?

Services that used to run on their own dedicated networks (telephone, storage, industrial control) now run over IP networks shared with everything else.

Why it matters

Convergence saves money but brings IP-network attacks to systems that were designed assuming physical isolation.

How it works

VoIP (voice over IP)

SIP sets up calls and RTP carries the audio. Threats: eavesdropping, toll fraud, caller ID spoofing, denial of service. Controls: SRTP (secure RTP) and SIP over TLS, a separate voice VLAN, session border controllers.

iSCSI

SCSI storage commands over TCP/IP. Without isolation and CHAP authentication, anyone on the storage network can mount disks. Put it on a dedicated, non-routed network.

FCoE (Fibre Channel over Ethernet)

storage networking on Ethernet; also kept on dedicated segments.

MPLS (Multiprotocol Label Switching)

carrier WAN that forwards on labels; it provides separation, not encryption.

Industrial protocols over IP

Modbus/TCP and DNP3 often lack authentication entirely; see IEC 62443.

🎯

On the job. During an internal assessment, list everything on the network speaking VoIP, iSCSI or industrial protocols, check whether it sits on its own segment, and whether authentication (SIP over TLS, CHAP, OPC UA security modes) is actually enabled rather than just supported.

Security angle

The common thread: isolate the converged traffic onto its own segment, and add the authentication and encryption the original protocol lacked.


Interview Questions

Q
What changed from WPA2 to WPA3, and why does it matter?
Model answer

WPA3-Personal replaces the pre-shared-key handshake with SAE, so an attacker who captures a handshake can no longer crack the passphrase offline — every guess needs a live interaction — and it adds forward secrecy. Protected management frames become mandatory, which stops deauthentication attacks. In practice it closes the "capture once, crack at leisure" attack that made WPA2-Personal weak with short passphrases.

Q
How does an evil-twin attack against corporate Wi-Fi work and how do you stop it?
Model answer

The attacker broadcasts the corporate network name, often after deauthenticating clients, and if laptops use PEAP without validating the RADIUS server certificate they complete the handshake with the fake access point and hand over credential hashes. The fix is EAP-TLS with client certificates, or at minimum enforcing server certificate and server-name validation on every client, plus wireless intrusion detection to spot rogue access points.

Q
Explain IPsec AH versus ESP, and transport versus tunnel mode.
Model answer

AH gives integrity and authentication over the whole packet including the outer IP header but no encryption, and it breaks through NAT; ESP gives encryption and integrity of the payload, so it's what everyone uses. Transport mode protects just the payload between two hosts, while tunnel mode wraps the entire original packet in a new IP header, which is what gateway-to-gateway site-to-site VPNs use. IKEv2 negotiates the keys on UDP 500, and NAT traversal moves ESP onto UDP 4500.

Q
Why is network access control with MAC authentication bypass weak?
Model answer

Because a MAC address is just a value the device announces, and it's trivially spoofed — an attacker unplugs a printer, copies its MAC and gets the printer's network access. It exists for devices that can't do 802.1X, so I'd put those devices in tightly restricted segments that only reach what they need, and profile their behaviour so a "printer" browsing file shares stands out.

Q
How would you segment a flat corporate network to limit ransomware spread?
Model answer

First map real traffic flows from flow logs so I know what actually needs to talk. Then carve out the crown jewels — domain controllers, backup servers, hypervisor management — into tightly restricted zones reachable only from admin workstations, block workstation-to-workstation SMB and RDP, and move servers into application-based segments with default-deny between them. Backups go on a segment ransomware can't reach with ordinary credentials, because that's what decides whether you recover.

Q
What's the security risk of running storage over IP with iSCSI?
Model answer

iSCSI sends disk commands over TCP, so anything that can reach the target and pass weak or no authentication can mount and read or wipe volumes. It was designed assuming a trusted storage network. Keep it on a dedicated, non-routed segment, enable CHAP authentication, and restrict which initiators each target accepts.